论文标题

使用游戏化的新型错误赏金实施的提案

Proposal of a Novel Bug Bounty Implementation Using Gamification

论文作者

O'Hare, Jamie, Shepherd, Lynsay A.

论文摘要

尽管很受欢迎,但自从其成立以来,漏洞赏金过程一直保持不变,并且游戏化方面的实施有限。现有文献认识到当前的方法会产生密集的资源需求,并可能遇到影响计划有效性的问题。本文提出了一个新颖的漏洞赏金过程,旨在减轻资源需求并减轻固有的问题。通过对其他黑客进行脆弱性验证和复制的报告验证的额外众包,客户组织可以以奖励更多参与者为代价来减少开销。游戏化元素的合并为货币奖励提供了替代品,并提出可能缓解漏洞赏金计划有效性问题。总的来说,拟议过程的特征似乎适合资源和预算受限的组织 - 此类高等教育机构。

Despite significant popularity, the bug bounty process has remained broadly unchanged since its inception, with limited implementation of gamification aspects. Existing literature recognises that current methods generate intensive resource demands, and can encounter issues impacting program effectiveness. This paper proposes a novel bug bounty process aiming to alleviate resource demands and mitigate inherent issues. Through the additional crowdsourcing of report verification where fellow hackers perform vulnerability verification and reproduction, the client organisation can reduce overheads at the cost of rewarding more participants. The incorporation of gamification elements provides a substitute for monetary rewards, as well as presenting possible mitigation of bug bounty program effectiveness issues. Collectively, traits of the proposed process appear appropriate for resource and budget-constrained organisations - such Higher Education institutions.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源